This policy explains how SC3I, a company incorporated under Estonian law and the data controller, processes personal data when you use 1p1: the mobile app, the web app, the 1p1 websites (1p1.fr and 1p1view.com) and the public tour pages.
01 Data we process
- Account data: email address, account name, password (stored in hashed form), account verification status and technical session identifiers.
- Content you create: tour titles and structure, room names, photos taken or chosen by the user, enhanced versions of those photos and related technical information.
- Property presentation and business profile: property type, town or city, price, floor area, description and, if you provide them, display name, agency name, phone number, WhatsApp number and contact email address.
- Purchases: offer purchased, amount, date, payment status, available credits and their expiry date. SC3I never receives your bank card details.
- Technical and security data: IP address and the information needed to prevent abuse, limit login attempts and diagnose errors.
- Published tour statistics: the total number of times each published tour is opened, on its public page and on the websites where it is embedded. This count sets no cookie and keeps no visitor identifier.
1p1 does not ask for your location and does not use your data for targeted advertising. Photos are re-encoded before they are synced so that their EXIF metadata, including GPS coordinates, is not kept.
02 Device access
Camera access is used only to take the photos you choose to add to a tour. Depending on your device, you can also choose an existing image. 1p1 does not access the camera in the background.
03 What becomes public
A tour stays private until you publish it. When you publish it, its public page and the embeddable tour can be viewed by anyone who has the link: photos, room names, property presentation and the contact options you chose to display. You can take a published tour offline at any time from the app; it also stops being accessible at the end of its publication period.
04 Purposes and legal bases
- creating and managing your account, authenticating you and securing your sessions;
- creating, saving, syncing, publishing and displaying your tours;
- enhancing a photo with artificial intelligence when you ask for it;
- processing your purchases and managing your credits;
- sending the emails needed to verify your address and reset your password;
- counting how often published tours are opened, to show you their statistics;
- protecting the service against abuse and keeping it running;
- measuring traffic on the website and the public pages (section 06).
This processing is necessary to provide the service you request. Security, abuse prevention and tour statistics are based on SC3I’s legitimate interest. Purchase data is kept to meet a legal accounting obligation. Audience measurement is based on your consent.
05 Recipients and service providers
Data is accessible only to authorised people at SC3I and to the service providers essential to the service. It is neither sold nor rented.
- Hosting and storage: hosting of the API and the database, OVHcloud object storage in France for photos.
- Emails: a provider that sends transactional emails.
- Payments: Stripe for card payments on Android and on the web, Apple for purchases made on the App Store. These providers process your payment data under their own privacy policies.
- AI photo enhancement: when you ask for a photo to be enhanced, only that photo is sent to Tencent Cloud International, which processes it and returns the enhanced version. This provider is located outside the European Union; no photo is sent to it unless you ask.
- Audience measurement: Google Analytics (Google), on the 1p1 websites and on public tour pages, under the conditions set out in section 06.
07 Retention
- Your account and content are kept for as long as you use the service, then deleted when the account is deleted, within 30 days at most.
- A deleted tour or photo is no longer offered in the app and its file is deleted from active storage.
- Residual copies in secure backups are erased within 90 days at most.
- Purchase data is kept for the period required by the applicable accounting legislation.
- Technical tokens have a limited lifetime and are revoked when they are no longer needed.
08 Security
Connections use HTTPS. Passwords are hashed, sensitive tokens are stored on the server as hashes, and access to unpublished content requires authentication. Since no measure can guarantee zero risk, SC3I maintains safeguards appropriate to the nature of the data processed.
09 Your responsibilities for photos
Before photographing a place, make sure you have the necessary permission. Avoid including people, documents, family photos, plates, valuables or other sensitive information in your images, especially in a tour you publish.
10 Your rights
Under the applicable law, you can ask for access to, rectification, erasure or restriction of your data, object to certain processing, withdraw your consent and exercise your right to data portability. You can delete your account by following the procedure on the Account deletion page.
You can lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), the authority responsible for SC3I, or with the data protection authority of your country of residence.
11 Contact
To exercise your rights or ask a question, contact SC3I at contact@1p1view.com. We may ask for the information strictly necessary to verify your identity.
12 Changes to this policy
This policy may change as the service or the regulations evolve. The date of the latest update is shown at the top of this page.